How a South African ISP Hacks Its Subscribers Each Month
defplex.wordpress.com
defplex.wordpress.com
At least make it an option.
(I don't know if it's just me, but I found the tone of the article a little alarmist, starting with "hacks" in the title. Then again, a lot of security researchers seem to write like that.)
It's copyright violation to modify copyrighted content before delivery without permission, especially when it's commercial content (ads) that is being injected. Maybe lawsuits could stop it.
Other examples from the US:
https://www.infoworld.com/article/2925839/net-neutrality/cod...
https://techcrunch.com/2012/04/06/now-you-know-hotels-inject...
Ironically, a similar argument is being used against adblockers, the other "benevolent MITM" application for modifying content: https://news.ycombinator.com/item?id=14978228 https://news.ycombinator.com/item?id=14990137
In other words, if those lawsuits succeed, they could set an unfortunate precedent against even personal "modification of content".
If I publish a website -- telling the users that we do not bother them with ads -- and another company then injects ads into that page, it not only violates the copyright, but it causes damage to my website's reputation, because most users aren't knowledgeable enough about the Web to understand that the ads are not put there by the publisher. It's probably even worse for websites that allow members to pay to have ads removed.
There are no guarantees on the internet that your packets will arrive intact and in order. That’s why we have tcp. What the ISP is doing may be sleazy, but it’s not violating some principle of computing.
[0] South Africanism for 'shit'
[1] https://mybroadband.co.za/vb/showthread.php/704472-Telkom-In...
[2] https://www.sadev.co.za/content/telkom-using-man-middle-atta...
I wonder if maybe it's because there's a lot of South African expats in New Zealand.
German: Kacke (the ck as usual indicates that this word may only be used with the voice raised beyond 85 dB and with at least 5 % spit by volume mixed into the air-stream).
20 years later when studying South African history I was able to subconsciously translate that one word. Die Mann praat kakk!
This was afaik the main reason, why YouTube went HTTPS-only very early compared to the rest of the internet. Some ISPs exchanged the video ads of YouTube with their own and lowered the resolution of videos to save bandwidth. YouTube's customers were very dissatisfied because it constantly broke and the video quality was very bad and thus HTTPS came to the rescue.
So more like "British Telecom" or "AT&T"
And while this isn't great this is a bit overplayed. They're more the kind of company that does something incompetently than one that does stuff maliciously.
Bigger companies also do that, Vodafone was compressing all images that went through their 3G service, and a ton of ISP inject / redirect HTTP traffic to tell you to pay the bills
I have however as of yet not seen them injecting JS or other content into HTTP pages.
Pro-Tip: their injection can only work on HTTP and not HTTPS so there is some relief from this inconvenient and dangerous code injection. Installing the HTTPS Everywhere plugin will help mitigate the injection and is a recommended plugin to run regardless. Alternatively install the Tor browser.
Sorry I had to be that guy. Please improve contrast on your blog.